Sarbanes IT Advantage.

12
Sarbanes Oxley Advanced IT Methodology. A Competitive Advantage Strategy. By Robert L. Brown Director Of Information

Transcript of Sarbanes IT Advantage.

Page 1: Sarbanes IT Advantage.

Sarbanes Oxley Advanced IT Methodology. A Competitive Advantage Strategy.

By Robert L. Brown

Director Of Information

Page 2: Sarbanes IT Advantage.

SARBANES ADVANTAGE 2

Information Technology Cycle,System Overview

Application Process Name Description

Process Supported. Eg. Revenues

Developer (Vendor Or Custom)

Change Management

Application Mgt

Data Management

Platform OS Network Physical

MAPICS EXTENDED SYSTEMS 7.0

ENTERPRISE ERP

MRP II, MPSP, AR, AP, GL, CUSTOMER SERVICE, ENGINEERING, CRP, INVENTORY

Vendor Developed

Base Product with some custom mods.

Reports in Cognos, Visual Basic 6.0 and Access 1997 Oracle 8i

Windows 2000 Server

Windows 2000-2003

Terminal Server: Windows NT Server 2000. HP file servers.

Page 3: Sarbanes IT Advantage.

SARBANES ADVANTAGE 3

FIXED ASSET CONTROL

FDC SOFTWARE, CARLISLE CHOICEMSACCESS TRACK COMPUTERLABELS FOR COMPUTER

EQUIPMENT.Application Process Description

Process Supported

Developer Vendor or Custom

Change Management

Application Management

Application Admin

Data Management Platform OS

Network Physcial

FDC

FIXED ASSET SOFTWARE

FIXED ASSETS VENDOR

BASE PRODUCT EXCEL

MS WINDOWS PC DESKTOP

LOCATED ON PC

MS ACCESS

FIXED ASSET TRACKING

FIXED, COMPUTER EQUIPME CUSTOM MIS ACCESS 97 MIS MIS WINDOWS

LOCATED PC

Page 4: Sarbanes IT Advantage.

SARBANES ADVANTAGE 4

MIS STRUCTURE

FORMAL MIS DEPARTMENTMANAGEMENT INFORMATION

SYSTEMS.MANUFACTURING INFORMATION

SYSTEMSMAPICS EXTENDED SYSTEMS 7.0

Page 5: Sarbanes IT Advantage.

SARBANES ADVANTAGE 5

MIS ORGANIZATION MOTION CONTROL MIS

– 2004 STURCTURE

P IT T S B U R G HK A N S A SA L T E C

S T O C K T O N C A L IF O R N IAA L T E C

M a rk V e llaP ro g ram m er

O n tario , C an a daA L T E C

L A N C A S T E , P AM O T IO N C O N T R O L

S to n ey S e a w e llN e tw o rk A d m in

C h a rlo tte sville , V AM O T IO N C O N T R O L

K e v in Ha n esA p p lic a tio n S u pp o rt

S o u th H ill, V aM O T IO N C O N T R O L

T o m K en d leM IS S U P P O RT

F R E D R IC K S B U R G , V AM O T IO N C O N T R O L

D ir o f In fo rm a tion S ys te m sC IB F A N D M O T IO N C O N T R O L

B o b B ro w nB lo om in g to n , In d ia na

Page 6: Sarbanes IT Advantage.

SARBANES ADVANTAGE 6

MIS REPSONSIBILITES

DIR OF MIS-BOB BROWN, MANAGERIAL CONTROL OF MIS DEPARTMENT. MARK VELLA , ALTEC, ONATRIO, CANADA, MAIN PROGRAMMER FOR MOTION

CONTROL AND ALTEC. EDI SUPPORT SPECIALIST. STONEY SEAWELL, NETWORK ADMINSITRATOR MOTION CONTROL AND ALETC.

VIRUS PROTECTION ,SECURITY, DATA CENTER SUPPORT. TOM KENDLE, MIS SUPPORT FREDRICKSBURG, VIRGINIA. MANUFACTURING

SUPPORT, SHOP FLOOR REPORTING, INFORMATION SPECIALIST FOR MANUFACTURING

KEVIN HANES, APPLICATION SUPPORT. MAIN SUPPORT ANALYST FOR THE MAPICS EXETNDED SYSTEMS APPLICATION. MIS BUSINESS ANALYST.

MARK VELLA, KEVIN HANES AND BOB BROWN ARE WELL VERSED IN THE MAPICS PRODUCT.

SUPPORT FOR ALL SITES IS DRIVEN TO THE PRIMARY SUPPORT PERSON THAT IS ON SITE.

MAPICS SUPPORT DESK IS ALSO PART OF THE SUPPORT LOGIC.

Page 7: Sarbanes IT Advantage.

SARBANES ADVANTAGE 7

SYSTEM ARCHITECTURE

To Gigabit Switch

HP 4108GL Switch

WIndows Load BalancingHub

DATASERV1Windows 2000 Advanced Server SP2

HP LC2000RDual P3 933MHZ

2 GB SDRAM(3) 9.1 GB SCSI DISK Operating System (3.5gb free)

Netraid 2M Ultra3 ControllerHP Gigabit Nic

Oracle/Pointman DatabasePrint Server

HP Rackstorage 12(4) 18 GB SCSI DISK DRIVES (21gb free)

Point.Man databases

APPSERV1Windows 2000 Advanced Server SP2Terminal Services Application Mode

HP LC2000RDual P3 800 MHZ

2 Gb SDRAM(3) 9.1 GB SCSI DISK (14gb free)

Netraid 3Si Ultra3 ControllerHP Gigabit Nic

Office2000Access97

Pointman ClientShopvue Client

APPSERV2Windows 2000 Advanced Server SP2Terminal Services Application Mode

HP LC2000RDual P3 800 MHZ

2 Gb SDRAM(3) 9.1 GB SCSI DISK (13gb free)

Netraid 3Si Ultra3 ControllerHP Gigabit Nic

Office2000Access97

Pointman ClientShopvue Client

SVSERV1SHOPVUE

Windows 2000 Server SP2HP LP2000R P3 1.4 GHZ

512 MB SDRAM(3) 18.1 GB SCSI DISK Operating System\Apps (24gb free)

Netraid 3Si Ultra3 ControllerHP 10/100 Nic

RIDGWAY1Windows 2000 Server SP2

HP LC2000RSingle P3 723MHZ

654 MB SDRAM(3) 9.1 GB SCSI DISK Operating System (3.5gb free)

Netraid 2M Ultra3 ControllerHP Gigabit Nic

File Server

HP Rackstorage 12(7) 9 GB SCSI DISK DRIVES (11gb free)

User Profiles/Home Directories

APPSERV4Windows 2000 Advanced Server SP2Terminal Services Application Mode

HP Proliant DL380 G3Dual P4 2.4 GHZ

2.5 GB DDR(3) 18.2 GB 15KRPM SCSI DISK (28gb free)

Smart Array 523 64MB SCSI ControllerDual HP Gigabit Nic

Office2000Access97

Pointman ClientShopvue Client

APPSERV3Windows 2000 Advanced Server SP2Terminal Services Application Mode

HP Proliant DL380 G3Dual P4 2.4 GHZ

2.5 GB DDR(3) 18.2 GB 15KRPM SCSI DISK (28gb free)

Smart Array 523 64MB SCSI ControllerDual HP Gigabit Nic

Office2000Access97

Pointman ClientShopvue Client

ToSw

itch

Page 8: Sarbanes IT Advantage.

SARBANES ADVANTAGE 8

TEACHING SARBANES: THE SOUND BUSINESS METHOD

SOUNDSMARTORGANIZTIONSUTILIZENECESSARYDOCUMENTATION

Page 9: Sarbanes IT Advantage.

SARBANES ADVANTAGE 9

SOUND PRINCIPLES

SARBANES OXLEY U=YOU NEED DOCUMENTATION

SMART ORGANIZATIONS UTILIZE NECESSARY DOCUMENTATION

Page 10: Sarbanes IT Advantage.

SARBANES ADVANTAGE 10

Why Sarbanes?

”The Goal” Creation of wealth. (POI) Protection of Information.

SARBANES.=(POW) Protection of Wealth.To protect stock holder value.To stop FRAUD. FRAUD an ugly word.Remember Fraud ends with a D.

Page 11: Sarbanes IT Advantage.

SARBANES ADVANTAGE 11

5 D’S OF SARBANES

DETECTION DETERENCE DEFENSE DOCUMENTATION DETERMINATION

Auditing Policy and Guidelines MIS SECURITY MIS SARBANES. MIS ETHICAL

STANDARDS.

Page 12: Sarbanes IT Advantage.

SARBANES ADVANTAGE 12

Key Issues

Near termSecurity and Password changes.Auditing of Information for Accuracy.

Long term Continuing Improvement in Security

Continuing documentation of processes.